When
a certificate and its private key are installed in the Windows machine
certificate store using Network and Security tool, access rights to the private
key are unnecessarily

granted to the operator group.




* Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed
*
Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable


Please refer to security bulletin BS-036, available on the Panorama CSIRT website:  https://my.codra.net/en-gb/csirt .

Project Subscriptions

Vendors Products
Panorama Suite Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 13:00:00 +0000

Type Values Removed Values Added
Description When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panorama CSIRT website:  https://my.codra.net/en-gb/csirt .
Title Unnecessary permissions on private keys of certificates installed by Network and Security Wizard
First Time appeared Codra
Codra panorama Suite
Weaknesses CWE-732
CPEs cpe:2.3:a:codra:panorama_suite:*:*:windows:*:*:*:*:*
cpe:2.3:a:codra:panorama_suite:panorama_suite_2025_updated_dec._25:*:windows:*:*:*:*:*
Vendors & Products Codra
Codra panorama Suite
References
Metrics cvssV4_0

{'score': 3.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CODRA

Published:

Updated: 2026-03-25T13:06:43.166Z

Reserved: 2026-03-24T09:12:20.014Z

Link: CVE-2026-4761

cve-icon Vulnrichment

Updated: 2026-03-25T13:06:38.567Z

cve-icon NVD

Status : Received

Published: 2026-03-25T13:16:28.310

Modified: 2026-03-25T13:16:28.310

Link: CVE-2026-4761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses